SAFA iconSAFA

Documentation

Deep dives on why agents should not hold credentials and how the secure-access pattern works, the architecture explainer, and the real recorded diagnosis.

Articles & deep dives

Article

Why Your AI Agent Should Never Hold Your SSH Keys

Agents are doing ops now — and handing them a key is exactly the wrong move. Process separation, allow-list policy, and user-presence authorization, with real evidence.

English ·
中文 Article

The SAFA Access Pattern: Every Resource, Topology, No Plaintext Password

How hosts, databases, object storage, caches, and services are registered with credentials that never become plaintext; trusted-setup password entry; jump routes and pinned identity; topology from evidence.

English ·
中文

Explanations & evidence

Explainer

How SAFA Works

The five-layer request flow, the credential isolation boundary, topology, security invariants, and the roadmap.

English · 中文
Live demo

A Real Diagnosis, Replayed

A real recorded SAFA session — NAS slowness investigated end-to-end, with the actual TOON evidence and boundary refusals.

English · 中文
See the real diagnosis View on GitHub